mirror of
https://github.com/auricom/home-cluster.git
synced 2025-12-30 18:27:26 +01:00
131 lines
3.9 KiB
YAML
131 lines
3.9 KiB
YAML
---
|
|
# yaml-language-server: $schema=https://json.schemastore.org/github-workflow.json
|
|
name: "Flux Diff"
|
|
|
|
on:
|
|
pull_request:
|
|
branches: ["main"]
|
|
paths: ["kubernetes/apps/**"]
|
|
|
|
concurrency:
|
|
group: ${{ github.workflow }}-${{ github.event.number || github.ref }}
|
|
cancel-in-progress: true
|
|
|
|
jobs:
|
|
changed-files:
|
|
name: Get Changed Files
|
|
runs-on: ubuntu-latest
|
|
outputs:
|
|
matrix: ${{ steps.changed-files.outputs.all_changed_and_modified_files }}
|
|
steps:
|
|
- name: Generate Token
|
|
uses: actions/create-github-app-token@v1
|
|
id: app-token
|
|
with:
|
|
app-id: "${{ secrets.BOT_APP_ID }}"
|
|
private-key: "${{ secrets.BOT_APP_PRIVATE_KEY }}"
|
|
|
|
- name: Checkout
|
|
uses: actions/checkout@v4
|
|
with:
|
|
token: "${{ steps.app-token.outputs.token }}"
|
|
fetch-depth: 0
|
|
|
|
- name: Get changed files
|
|
id: changed-files
|
|
uses: tj-actions/changed-files@v41
|
|
with:
|
|
files: kubernetes/**
|
|
safe_output: false
|
|
dir_names: true
|
|
dir_names_max_depth: 2
|
|
json: true
|
|
quotepath: false
|
|
escape_json: false
|
|
|
|
- name: List all changed files
|
|
run: echo "${{ steps.changed-files.outputs.all_changed_and_modified_files }}"
|
|
|
|
flux-diff:
|
|
name: Flux Diff
|
|
runs-on: ubuntu-latest
|
|
needs: ["changed-files"]
|
|
permissions:
|
|
pull-requests: write
|
|
strategy:
|
|
matrix:
|
|
paths: ${{ fromJSON(needs.changed-files.outputs.matrix) }}
|
|
resources: ["helmrelease", "kustomization"]
|
|
max-parallel: 4
|
|
fail-fast: false
|
|
steps:
|
|
- name: Generate Token
|
|
uses: actions/create-github-app-token@v1
|
|
id: app-token
|
|
with:
|
|
app-id: "${{ secrets.BOT_APP_ID }}"
|
|
private-key: "${{ secrets.BOT_APP_PRIVATE_KEY }}"
|
|
|
|
- name: Setup System Tools
|
|
shell: bash
|
|
run: sudo apt-get -qq update && sudo apt-get -qq install --no-install-recommends -y curl git
|
|
|
|
- name: Checkout Live Branch
|
|
uses: actions/checkout@v4
|
|
with:
|
|
token: "${{ steps.app-token.outputs.token }}"
|
|
ref: main
|
|
path: default
|
|
|
|
- name: Checkout PR branch
|
|
uses: actions/checkout@v4
|
|
with:
|
|
token: "${{ steps.app-token.outputs.token }}"
|
|
path: pull
|
|
|
|
- name: Diff Resources
|
|
uses: docker://ghcr.io/allenporter/flux-local:main
|
|
with:
|
|
args: >-
|
|
--log-level DEBUG
|
|
diff ${{ matrix.resources }}
|
|
--unified 6
|
|
--path-orig /github/workspace/default/${{ matrix.paths }}
|
|
--path /github/workspace/pull/${{ matrix.paths }}
|
|
--strip-attrs "helm.sh/chart,checksum/config,app.kubernetes.io/version,chart"
|
|
--limit-bytes 10000
|
|
--all-namespaces
|
|
--sources "home-ops-kubernetes"
|
|
--output-file diff.patch
|
|
|
|
- name: Generate Diff
|
|
id: diff
|
|
run: |
|
|
cat diff.patch
|
|
echo "diff<<EOF" >> $GITHUB_OUTPUT
|
|
cat diff.patch >> $GITHUB_OUTPUT
|
|
echo "EOF" >> $GITHUB_OUTPUT
|
|
|
|
- if: ${{ steps.diff.outputs.diff != '' }}
|
|
name: Add comment
|
|
uses: mshick/add-pr-comment@v2.8.1
|
|
with:
|
|
repo-token: "${{ steps.app-token.outputs.token }}"
|
|
message-id: "${{ github.event.pull_request.number }}/${{ matrix.paths }}/${{ matrix.resources }}"
|
|
message-failure: Diff was not successful
|
|
message: |
|
|
```diff
|
|
${{ steps.diff.outputs.diff }}
|
|
```
|
|
|
|
# Summarize matrix https://github.community/t/status-check-for-a-matrix-jobs/127354/7
|
|
flux-diff-success:
|
|
if: ${{ always() }}
|
|
needs: ["flux-diff"]
|
|
name: Flux diff successful
|
|
runs-on: ubuntu-latest
|
|
steps:
|
|
- if: ${{ contains(needs.*.result, 'failure') || contains(needs.*.result, 'cancelled') }}
|
|
name: Check matrix status
|
|
run: exit 1
|